{
  "osquery_time": "1592478128",
  "datetime": "2020-06-05T13:25:27.5386183Z",
  "source": "Security",
  "provider_name": "Microsoft-Windows-Security-Auditing",
  "provider_guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}",
  "event_id": "4672",
  "task_id": "12548",
  "level": "0",
  "keywords": "0x8020000000000000",
  "data": "{\"EventData\":{\"SubjectUserSid\":\"S-1-5-18\",\"SubjectUserName\":\"SYSTEM\",\"SubjectDomainName\":\"NT AUTHORITY\",\"SubjectLogonId\":\"0x3e7\",\"PrivilegeList\":\"SeAssignPrimaryTokenPrivilege\\n\\t\\t\\tSeTcbPrivilege\\n\\t\\t\\tSeSecurityPrivilege\\n\\t\\t\\tSeTakeOwnershipPrivilege\\n\\t\\t\\tSeLoadDriverPrivilege\\n\\t\\t\\tSeBackupPrivilege\\n\\t\\t\\tSeRestorePrivilege\\n\\t\\t\\tSeDebugPrivilege\\n\\t\\t\\tSeAuditPrivilege\\n\\t\\t\\tSeSystemEnvironmentPrivilege\\n\\t\\t\\tSeImpersonatePrivilege\\n\\t\\t\\tSeDelegateSessionUserImpersonatePrivilege\"}}",
  "computer_name": "DESKTOP-4AR7BIA"
}
